Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VirusTotal/Hybrid-Analysis Result (Same as Firefox) #12

Closed
antuketot76 opened this issue Dec 16, 2018 · 4 comments
Closed

VirusTotal/Hybrid-Analysis Result (Same as Firefox) #12

antuketot76 opened this issue Dec 16, 2018 · 4 comments
Labels
help wanted Extra attention is needed wontfix This will not be worked on

Comments

@antuketot76
Copy link

Below are some my analysis inside HA and VT.

image

Hybrid Analysis - HERE
VirusTotal - HERE

But there is 2 file detected as malicious

image

Check it out for file intergrity

@intika intika changed the title WHITELISTED in Hybrid Analysis VirusTotal/Hybrid-Analysis Result Dec 17, 2018
@intika
Copy link
Owner

intika commented Dec 17, 2018

Those files are coming from the official Mozilla Firefox built, as the project is young i am not distributing a built from sources version.

Those files are signed with mozilla certificates.

You will get the exact same result with the official Firefox files because they are the same not modified you can try that out Firefox Setup 63.0.3.exe it's the sames files (to extract the exe, once you run it, it create those files in %tmp%)

There is not much we can do about that other than asking AV company to whitelist those files ... mozilla did not do it so... this is because of Filseclab and Cylance. and they are doing so because of 3 possibles reasons.

  1. Analysis indicate an installer and they are blacklisting the file because it does what it does which is installing an application
    Or
  2. Some malware are using official mozilla installer to install itself and engineers at the av company did not bother to make a deep analysis.
    Or
  3. A lot of av company give false positive just to say there is something where in fact there is nothing.

They are mozilla signed anyway so it's trust-able.

Also Librefox could be applied manually without the installer.

@intika intika changed the title VirusTotal/Hybrid-Analysis Result VirusTotal/Hybrid-Analysis Result (Same as Firefox) Dec 17, 2018
@intika
Copy link
Owner

intika commented Dec 17, 2018

I forget thank you for contributing and reporting back this it's appreciated :)

@brainscar
Copy link
Contributor

@intika is right.

It goes like this:

Firefox Setup 63.0.3.exe > setup.exe (in tmp) > system.dll and nsExec.dll

I have uploaded them here (from the official Mozilla build) :

https://www.virustotal.com/#/file-analysis/YjU1ZjdmMWIxN2MzOTAxODkxMGMyMzEwOGY5MjkwODI6MTU0NTE3MzAxOA==

https://www.virustotal.com/#/file-analysis/MTdlZDFjODZiZDY3ZTc4YWRlNDcxMmJlNDhhN2QyYmQ6MTU0NTE3MzA0Nw==

Nothing we can do about it.

@intika intika added wontfix This will not be worked on help wanted Extra attention is needed labels Dec 19, 2018
@intika
Copy link
Owner

intika commented Dec 19, 2018

Closing this as wontfix... thanks again for taking time for the report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Extra attention is needed wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

3 participants